
Victims have been identified in Africa, including Kenya and Uganda
NAIROBI, Kenya , September 21, 2026/ — Kaspersky’s
(www.Kaspersky.co.za) Global Research and Analysis Team (GReAT) has
uncovered a sophisticated new multi-stage campaign targeting both
individual users and organisations. The campaign relies on a previously
unknown malware strain distributed through torrent trackers disguised as
popular films, including The Odyssey. One of the popular public archives
of torrent files was compromised and was then used to deliver the
malicious payload. Several hundred victims have been identified in a
multitude of countries, including Russia, Türkiye, Japan, Kenya,
Uganda, and Colombia, as well as in several European countries such as
Spain, the Netherlands, Belgium, Germany and others. Victims already
identified include organisations operating in the enterprise,
government, IT, consulting, retail, transportation, and agriculture
sectors. The campaign has been active since at least mid-August and
remains ongoing.
The attack itself is built as a multi-stage framework composed of
several elements that work together at different stages of the
intrusion. At the initial stage, the malware uses a loader capable of
detecting antivirus sandboxes, which are isolated testing environments
security products use to safely examine suspicious files. This allows
the malware to determine whether it is being analysed and, if so, evade
detection or hinder further investigation. Once active on a victim’s
device, the malware deploys additional modules that expand its
capabilities. These modules allow it to establish persistence, so it
remains on the system after a reboot even after it has been terminated,
bypass User Account Control (UAC) to gain administrator privileges in
Windows without triggering the usual warning prompt and ultimately
provide the attackers with remote access to the compromised machine.
To retrieve the address of its command-and-control server, the malware
uses the Solana blockchain. This gives the attackers a more resilient
way to maintain control over their infrastructure and makes the campaign
harder to disrupt through blocking or takedown efforts.
“The campaign is notable for combining a common lure with a
sophisticated technical design. By disguising malware as torrents for
popular films, the attackers increase the likelihood that unsuspecting
users will download it. Once launched, the multi-stage malware is
designed to evade detection, establish persistence, and provide the
attackers with remote access to infected devices. Users should be
especially cautious with files downloaded from unofficial sources, as
even seemingly harmless entertainment content can serve as a vehicle for
compromise,” says Konstantin Isakov, security expert at Kaspersky
GReAT.
To stay safe Kaspersky recommends that users:
- Be cautious with downloads. It’s safer to install games and mods
only from official sources or reputable websites. Unofficial sources may
contain malware. - Use a strong security solution, such as Kaspersky Premium
(https://apo-opa.co/4ro5DJx [7]), on all computers and mobile devices.
It will warn you about potential threats and prevent infection. - Never disable antivirus or security tools to download any files or
software.
Organisations are recommended to:
- Implement clear guidelines for the use of third-party software on
work devices. - Use all-encompassing solutions from the Kaspersky Next
(https://apo-opa.co/4y66BNb [8]) product line that provide real-time
protection, threat visibility, and the investigation and response
capabilities of EPP, EDR and XDR. Depending on your current needs and
available resources, you can choose the most relevant solution within
this product line and easily migrate to another one if your
cybersecurity requirements change. - Provide your InfoSec professionals with an in-depth visibility into
cyberthreats targeting your organisation. The latest Kaspersky Threat
Intelligence (https://apo-opa.co/4hdVU5r [9]) will provide them with
rich and meaningful context across the entire incident management cycle
and helps them identify cyber risks in a timely manner. - If your company lacks cybersecurity expertise, adopt managed
security services from Kaspersky such as Compromise Assessment
(https://apo-opa.co/4h1EtF0 [10]), Managed Detection and Response
(https://apo-opa.co/4izoQFY [11]) and/or Incident Response
(https://apo-opa.co/4ygPiJp [12]) which cover the entire incident
management cycle – from threat identification to continuous protection
and remediation.
Kaspersky security solutions detect the described malware. The full
technical analysis is available on www.Securelist.com.
About Kaspersky:
Kaspersky is a global cybersecurity and digital privacy company founded
in 1997. Innovating the industry with a Cyber Immunity approach,
Kaspersky safeguards consumers, businesses, critical infrastructure, and
governments from cyberthreats, with over a billion devices protected to
date. Kaspersky ensures Cybersecurity True to Business, focusing on
providing clear outcomes, protecting revenue, easing workloads and
preventing downtime. Kaspersky’s deep threat intelligence and security
expertise is constantly transforming into innovative solutions and
services for organizations of every size, from small businesses to large
enterprises, combining proven AI-driven protection technologies with
simple management and expert support. Recognized in independent tests
and trusted by millions of individuals worldwide and nearly 200,000
organizations, Kaspersky helps detect threats earlier, respond faster
and operate with greater confidence and freedom, protecting what matters
most to our clients. Learn more at (www.Kaspersky.co.za [19]).





